Courseiva
hardMultiple ChoiceObjective-mapped

300-410 Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show ip nat translations

Pro Inside global Inside local Outside local Outside global udp 192.0.2.10:1234 10.0.0.10:1234 203.0.113.5:53 203.0.113.5:53 tcp 192.0.2.10:5678 10.0.0.10:5678 198.51.100.20:80 198.51.100.20:80 --- 192.0.2.11 10.0.0.11 --- ---

R1# show ip nat statistics

Total active translations: 3 (0 static, 3 dynamic; 3 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 100 Misses: 0 CEF Translated packets: 100, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source

[Id] ip nat pool POOL1 192.0.2.10 192.0.2.20 netmask 255.255.255.240

refcount 3 map-id 1 overload

[Id] ip nat inside source list ACL1 pool POOL1 overload

refcount 3

Based on this output, what is the problem?

⚠ Common exam trap

Cisco often tests the distinction between simple NAT and PAT by showing a translation entry without ports, leading candidates to incorrectly assume the pool is exhausted or that static NAT is in use, when the real issue is a misconfigured ACL or route-map that allows non-PAT traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The third translation is not using PAT, indicating a possible ACL or route-map misconfiguration.

The third translation lacks a protocol and port number, meaning it is a simple dynamic NAT entry without Port Address Translation (PAT). Since the pool is configured with the `overload` keyword, all translations should use PAT to share the pool addresses. The presence of a non-PAT translation indicates that the ACL or route-map used to match traffic for NAT is misconfigured, causing some traffic to be translated without port multiplexing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The third translation is not using PAT, indicating a possible ACL or route-map misconfiguration.

    Why this is correct

    The overload configuration should create PAT entries with protocol/port. The third entry without protocol suggests the traffic from 10.0.0.11 is not being matched by the same ACL or is using a different pool.

  • The pool is exhausted because 192.0.2.10 is used twice.

    Why it's wrong here

    PAT allows multiple inside hosts to share the same global address; this is normal. Exhaustion would occur if all pool addresses were used without overload.

  • The outside interface is misconfigured as inside.

    Why it's wrong here

    The statistics show correct interface assignment.

  • The NAT translations are all static.

    Why it's wrong here

    The statistics clearly show 0 static translations.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.